Photo by .Net Hub Kathmandu
I attended the Microsoft Build 2026 // localhost : Kathmandu Event organized by .NetHub Kathmandu. This was an incredibly educational & insightful experience. As a simple student who happened to find out about this event in LinkedIn, I signed up on a whim and was thrilled to get a seat.
The event was held on Maitri Holdings , Pulchowk, Lalitpur . It started from 12 PM upto 5 PM on Sunday, June 14, 2026. The schedule featured three main technical sessions, followed by a brief introduction to Maitri Holdings and the job opportunities available within the company.
First Session by Farhad Hossain Rakib
The event kicked off with a virtual session by Farhad Hossain Rakib, broadcasting live from his office in Bangladesh. His talk focused on a massive shift happening in tech: “The Rise of AI Agents in Modern Software Development.” . For anyone in development, we all know how APIs are the backbone of the modern Application Infrastructure ! They handle everything in backend to make a smooth customer experience. In this session Farhad introduced us to a major evolution : Traditional Workflows vs. Agentic Workflows. Instead of traditional workflows where there are fixed predefined rules for code, Agentic AI introduces systems that can adapt & solve problems. He broke this down into real world examples like in ride-sharing and restaurant management, showing how an AI Agent can dynamically manage complex tasks . We were also introduced to AI Foundry, a toolkit designed specifically for building these next-generation Agentic APIs.
Second Session by Kailash Bohora
The second session was brought back to the live stage with Kailash Bohora, who delivered another important talk titled: “Breaking & securing .Net Applications”. As someon still in his foundational phase of Learning Development , this session was an eye-opener for me. It made me realise that building the software is only the half, protecting it is just as important. Kailash Sir introduced us to essential industry security frameworks and concepts, including OWASP (the standard blueprint for web application security) and SBOM (Software Bill of Materials, which acts like an ingredient list for tracking software dependencies).
Another major highlight of his talk was File Upload Security. Its common to take uploading a profile picture or a document for granted but Kailash broke down how easily these features could be exploited if developers aren’t careful. Here is a checklist of best practices to follow:
- Strict Extension Validation: Always restrict uploads to specific formats (like .png or .jpeg for photos, and .pdf or .csv for documents).
- Watch for Sneaky Extensions: Check for double extensions (like virus.png.exe) and case-sensitivity issues (like .PNG vs .png).
- Set File Size Limits: Prevent users from crashing your server by uploading massive, unoptimized files.
- Verify Magic Bytes: Don’t just trust the file extension name. Checking the “Magic Bytes” , the actual signature bytes at the beginning of a file which ensures that a file pretending to be an image isn’t secretly a malicious script.
We had a lunch break after these 2 sessions, the lunch & networking break also turned very fruitful in this event. The cafeteria at Maitri Holdings seemed very good.
Third Session by Nabaraj Ghimire
The final session was presented by Nabaraj Ghimire, who dove into a cutting-edge topic: “AI Native Data Applications with SQL MCP.” This session perfectly filled the gap between the AI concepts and backend database management.
For those unfamiliar, MCP stands for Model Context Protocol — essentially a standardized bridge that allows AI models to securely interact with data sources. Nabaraj broke down how to build these intelligent, data-driven systems safely:
- MCP Fundamentals & Server Responsibilities: We learned how an MCP server acts similarly to a traditional API endpoint, serving as the secure gatekeeper between the AI and our data.
- Tool Design & Query Builders: Instead of letting the AI guess how to interact with a database, developers design specific tools and query builders that give the AI a structured way to request data.
- The Danger of Raw SQL: A major takeaway was learning why you should never use raw SQL with AI. Giving an AI model direct, unrestricted access to execute code on your database is a massive security risk.
- The Auth Layer: To fix this, Nabaraj emphasized building a strict authentication layer within the MCP server to control exactly what the AI can see and do.
To close out an incredible day, the team gave us a brief introduction to Maitri Holdings Ltd., the company that hosted the event. They shared insights/experiences into their workplace culture and highlighted exciting job and internship opportunities within the company.
Group photo with Participants & Organizers
From AI agents and advanced .NET security to AI-native data architecture, Microsoft Build 2026 // localhost : Kathmandu gave me a whole new perspective on the tech field. It showed me just how fast the industry is moving and inspired me to keep building, learning, and stepping out of my comfort zone. The sessions throughout the events were very good & gave me a new perspective towards the tech field
Hello Readers! I am a student sharing my experiences as I step into the tech world. If you enjoyed reading about my time at this event, please consider giving this post a follow! You can also connect with me across my socials here:
Website: https://www.samratparajuli0.com.np/LinkedIn: https://linkedin.com/in/samratvsnGithub: https://github.com/SamratVsnX: https://x.com/SamratVsnInstagram: https://www.instagram.com/samratvsn/
